Question 66

You have an Azure subscription that uses Azure Defender.
You plan to use Azure Security Center workflow automation to respond to Azure Defender threat alerts.
You need to create an Azure policy that will perform threat remediation automatically.
What should you include in the solution? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Question 67

You need to remediate active attacks to meet the technical requirements.
What should you include in the solution?
  • Question 68

    You have an Azure subscription that has Azure Defender enabled for all supported resource types.
    You create an Azure logic app named LA1.
    You plan to use LA1 to automatically remediate security risks detected in Azure Security Center.
    You need to test LA1 in Security Center.
    What should you do? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 69

    You are investigating an incident by using Microsoft 365 Defender.
    You need to create an advanced hunting query to detect failed sign-in authentications on three devices named CFOLaptop, CEOLaptop, and COOLaptop.
    How should you complete the query? To answer, select the appropriate options in the answer area.
    NOTE: Each correct selection is worth one point.

    Question 70

    You have a Microsoft Sentinel workspace named Workspaces
    You configure Workspace1 to collect DNS events and deploy the Advanced Security information Model (ASIM) unifying parser for the DNS schema.
    You need to query the ASIM DNS schema to list all the DNS events from the last 24 hours that have a response code of 'NXDOMAIN' and were aggregated by the source IP address in 15-minute intervals. The solution must maximize query performance.
    How should you complete the query? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point.